A bot that can enter a subject line and body message? Geez ..
Yes, and these bots can even more!
I hardcoded the name of the comment-sender in the form - meaning the normal user can't change that, but the bots came up with always new names sent to the form and at the end saved to the comment!
So the bot did in my case:
1) Register a new user every 10 minutes from a new IP using one out of 9 e-mail domains where the user_name was always
namenumber and the e-mail always
namenumber@domain.com/org/net etc
2) Activate the new user (e-mail activation is turned on on my site)
3) Log in
4) Visit a random image
5) Post a comment with a random name/subject and a long chain of links to pr0n sites and other
After implementing the Security-codes the bot is still visiting my site evey 10 minutes and trying to enter register.php 3x, login.php 1x and some details.php??image_id=xxxx 2x (see the attached image)
But no new users are registered and no new spam-comments are added...
I guessed that no one would code a bot just to spam
my tiny site and so I searched the web and found
some script-bots on the internet, specialized for 4images sites, 4images exploits etc. ...
horrible!
Today my web-host called me, that I have to change my scripts (not only 4images), because the sites is being continuously
attacked...